Junglewise Threat Intelligence

CVE-2025-14014: NTN Smart Panel unrestricted file upload and ACL bypass

CVE-2025-14014 · Severity: critical · CVSS 9.8 · Published 2026-02-12

Executive brief

NTN Smart Panel, a management interface for industrial or commercial hardware, contains a critical security flaw that allows unauthorized users to upload malicious files. By exploiting this weakness, an attacker can bypass security controls and gain full control over the system. This could lead to the theft of sensitive data, complete service disruption, or the use of the device as a foothold for further attacks on the corporate network.

Technical details

A critical vulnerability (CWE-434) exists in NTN Smart Panel versions prior to 20251215 due to insufficient validation of uploaded files. The flaw allows an unauthenticated remote attacker to upload files with dangerous extensions to the server. Because the application also fails to properly enforce Access Control Lists (ACLs) on certain functionalities, an attacker can leverage the uploaded files to achieve remote code execution (RCE). This grants the attacker full system access with the privileges of the web service, potentially leading to complete compromise of the confidentiality, integrity, and availability of the host.

Affected products

  • NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd. Co. Smart Panel before 20251215

Timeline

  • 2026-02-12: disclosed
  • 2026-02-12: advisory

References